PT-2017-2634 · D Link · D-Link Dir-615 Wireless N 300 Router

Published

2017-06-11

·

Updated

2023-04-26

·

CVE-2017-9542

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-615 Wireless N 300 Router
Description The issue is related to weaknesses in the authentication procedure of the router's firmware. It can be exploited by a remote attacker using a modified POST request to the "login.cgi" endpoint, allowing them to bypass authentication. The problem arises because the router fails to properly validate the password field. Successful exploitation enables an attacker to gain control of the affected device.
Recommendations For D-Link DIR-615 Wireless N 300 Router, consider disabling access to the "login.cgi" endpoint until a patch is available to prevent exploitation. Restricting access to this endpoint can minimize the risk of unauthorized control. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2017-01861
CVE-2017-9542

Affected Products

D-Link Dir-615 Wireless N 300 Router